UK Data Protection

The UK GDPR Is the EU Text With Words Swapped Out, and Then Rewritten

Key Takeaways

  • Article 8(1) of the UK GDPR sets the age at which a child can consent to information society services at 13, rather than the 16 the EU text defaults to
  • The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025; the ICO records all its data protection provisions as in force
  • Transfers out of the UK turn on whether protection after transfer is "not materially lower" than under UK law, a test the Act writes into the legislation itself
  • EU SCCs are not valid on their own for UK restricted transfers; the ICO's IDTA or its Addendum to the EU SCCs carries them
  • The ICO fined Reddit, Inc. £14,472,500 in February 2026 over age assurance; Reddit appealed to the First-tier Tribunal on 1 April 2026

A Regulation That Was Copied, Then Edited

Most national privacy regimes were drafted. The UK's was inherited. When the Brexit transition period ended on 31 December 2020, Regulation (EU) 2016/679 did not stop applying in the UK so much as it was retained, renamed and amended in place. legislation.gov.uk publishes it under the title "Regulation (EU) 2016/679 … (United Kingdom General Data Protection Regulation)" — the EU citation intact, the UK label appended in brackets.

That publication history is not a curiosity. It is the most useful thing to know about the regime, because it tells you where to look for the differences. The UK GDPR is displayed with editorial annotations marking every amendment: an F-number against a phrase means that phrase was substituted, and the note beneath it names the instrument that did the substituting. Reading the UK text alongside the EU text is therefore a matter of reading the footnotes, not of comparing two independently drafted statutes.

The instrument responsible for most of the 2020 edits is the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019. Its method was largely mechanical — it swapped institutional and geographic terms so the machinery would keep running with the UK's own institutions in the slots the EU's had occupied. But mechanical substitution is not the same as no change, and in at least one place the 2019 Regulations moved a rule rather than merely relabelling it.

Where the Text Already Differed on Day One

The clearest example concerns children. Article 8(1) of the EU GDPR sets 16 as the age at which a child can consent on their own behalf to information society services, and permits member states to lower that to no less than 13. The UK exercised that option in section 9 of the Data Protection Act 2018. After Brexit there was no member state discretion to exercise, so the rule moved: section 9 was omitted with effect from 31 December 2020, and the number was written straight into Article 8(1) of the UK GDPR, which now provides that processing a child's personal data is lawful where the child is at least 13.

A reader consulting the DPA 2018 alone would find an omitted section and no age at all. A reader consulting the EU Regulation would find 16. The operative number sits in a third place, and only the annotated UK text shows it.

Territorial scope was relabelled rather than moved. Article 3 of the UK GDPR reads as the EU provision does, with "the United Kingdom" substituted for "the Union" throughout. Article 3(1) reaches processing in the context of the activities of an establishment in the UK wherever the processing happens. Article 3(2) reaches controllers and processors with no UK establishment where the processing relates to data subjects who are in the UK and concerns either the offering of goods or services to them, payment required or not, or the monitoring of their behaviour as far as that behaviour takes place within the UK.

The consequence for a company outside both blocs is arithmetic rather than legal analysis: conduct aimed at people in the UK and conduct aimed at people in the EU are now assessed under two instruments with the same architecture and diverging detail. Article 27 carries its own version of this — where Article 3(2) applies, the controller or processor "shall designate in writing a representative" in the United Kingdom, and that representative is to be addressed by the Commissioner and by data subjects in addition to or instead of the controller. A company caught by both Article 3(2) provisions is designating two representatives, in two places, under two Article 27s.

The Data (Use and Access) Act 2025 Rewrote Chunks of It

The second wave of divergence was deliberate. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and the ICO records that all of its provisions affecting data protection law and the Privacy and Electronic Communications Regulations are now in force, commenced in stages by regulations rather than all at once.

The Department for Science, Innovation and Technology's factsheet on the UK GDPR and DPA changes maps each measure to the provision it amends. The edits are structural rather than cosmetic:

  • Recognised legitimate interests. Section 70 amends Article 6 and Schedule 4 inserts a new Annex 1 into the UK GDPR, creating a lawful ground for a defined list — crime prevention, safeguarding vulnerable people, responding to emergencies, safeguarding national security, and assisting other bodies with public interest tasks sanctioned by law. Necessity is still required; the balancing assessment that Article 6(1)(f) demands is not
  • Purpose limitation. Section 71 amends Articles 5 and 6 and inserts a new Article 8A, setting out when further processing is compatible with the original purpose, including where there is a change of controller
  • Automated decision-making. Section 80 replaces Article 22 of the UK GDPR and section 14 of the DPA 2018 with new Articles 22A to 22D. The framing shifts from a general prohibition subject to exceptions to a permission subject to safeguards — information about significant decisions, a route to make representations and challenge them, and access to human intervention
  • Children's higher protection matters. Section 81 adds Article 25(1B), requiring information society services likely to be accessed by children to take account of specified matters when designing processing — how best to protect and support children, that children may be less aware of the risks, and that children have different needs at different ages and stages of development
  • Subject access. Sections 75 to 78 and 104 amend Articles 12 to 15 and insert a new Article 12A, introducing a "stop the clock" mechanism that pauses the response period while the controller seeks clarification, and codifying the case law that searches be reasonable and proportionate
  • Research. Sections 67, 68, 86 and 87 amend Article 4 and add a new Chapter 8A containing Articles 84A to 84D, stating in the legislation that scientific research includes commercial research, permitting broad consent to an area of research subject to conditions, and consolidating the research safeguards

The pattern running through these is relocation of law from recitals into operative text. The factsheet says so explicitly about research — "the concept of 'broad consent' for research purposes was previously found in the UK GDPR recitals" — and about the definition of scientific research, which had rested on recital 159. Recitals in retained EU law occupy an uncertain interpretive position in a UK court, so moving a rule into an Article changes its weight as well as its address.

Transfers Out of the UK Turn on "Not Materially Lower"

Chapter 5 of the UK GDPR was amended by section 85 and Schedules 7 to 9 of the Act, and the amendment supplies something the EU text leaves to case law and guidance: an articulated standard.

Two versions of the same test now sit in the legislation. For the Secretary of State deciding whether to approve transfers to a third country, the question is whether that country has a standard of data protection "not materially lower" than the UK's. For an exporter relying on an alternative mechanism such as standard contractual clauses, the test is met if the level of protection for a data subject after transfer will be not materially lower than under UK law, and the Act requires controllers and processors to act reasonably and proportionately in assessing it. The DSIT factsheet also records that the four-year review period for adequacy regulations is removed while ongoing monitoring is retained, and that the Secretary of State gains a power to recognise new transfer mechanisms.

The contractual machinery is the ICO's own. Its guidance on standard data protection clauses sets out two instruments: the International Data Transfer Agreement (IDTA), and the International Data Transfer Addendum to the European Commission standard contractual clauses. On the relationship between them the ICO is unambiguous — the EU SCCs, issued by the Commission on 4 June 2021, "are not valid on their own for restricted transfers under the UK GDPR", but the Addendum lets an exporter rely on them.

The IDTA is built in four parts: Tables, Extra Protection Clauses, Commercial Clauses, and Mandatory Clauses. Part 1 and Part 4 are compulsory; Parts 2 and 3 are optional. The ICO states that the IDTA ceases to be a safeguard if the Part 1 information is not provided or the Part 4 Mandatory Clauses are changed beyond what Part 4 Section 5 permits. Either instrument sits alongside a transfer risk assessment rather than replacing it: on the ICO's account a restricted transfer can be made where the parties enter a contract incorporating standard data protection clauses and the exporter completes a TRA confirming the standard of protection is not materially lower after transfer.

Adequacy Runs in Both Directions

Everything above concerns data leaving the UK. The reciprocal question — whether data may leave the EEA for the UK without further safeguards — is decided in Brussels, and it was open for most of 2025.

The European Commission's adequacy decisions page records the sequence. Technical extensions of the UK adequacy decisions under both the GDPR and the Law Enforcement Directive were published on 24 June 2025. Renewal decisions followed on 19 December 2025, and the Commission now lists the United Kingdom among recognised jurisdictions "under the GDPR and the LED, as amended in December 2025 through one renewal decision under the GDPR and one renewal decision under the LED".

The UK's position on that list is unusual in one respect the Commission spells out: with the exception of the United Kingdom, the adequacy decisions do not cover data exchanges in the law enforcement sector governed by Article 36 of Directive (EU) 2016/680. The UK holds adequacy on both tracks.

The Data Protection Act 2018 Does What a Regulation Cannot

The UK GDPR does not stand alone. The Data Protection Act 2018 supplies the domestic scaffolding, and its structure explains which questions it answers:

PartSubject
Part 1Preliminary — definitions and scope
Part 2General processing — application of the UK GDPR, lawfulness, special category data, rights, and exemptions
Part 3Law enforcement processing by competent authorities
Part 4Intelligence services processing
Part 5The Information Commissioner — functions, codes of practice, audit powers
Part 6Enforcement
Part 7Supplementary and final provision

Two features of that division matter for a company reading the Regulation and wondering why an answer is missing. Exemptions are one: section 15 and Schedule 2 carry the derogations, so a controller asking whether an exemption covers a disclosure is reading the Act rather than the Regulation. Enforcement is the other. Part 6 holds the penalty powers, and section 157 fixes their ceiling.

Section 157 defines two tiers in sterling rather than euro. The higher maximum amount is £17,500,000 or 4% of an undertaking's total annual worldwide turnover in the preceding financial year, whichever is higher — and £17,500,000 in any other case. The standard maximum amount is £8,700,000 or 2% of turnover on the same "whichever is higher" formula, and £8,700,000 otherwise.

What ICO Enforcement Has Actually Looked Like

The most substantial recent monetary penalty concerns the age threshold the 2019 EU Exit Regulations wrote into Article 8(1). On 23 February 2026 the ICO imposed a penalty of £14,472,500 on Reddit, Inc. for infringing Articles 5(1)(a), 6, 8 and 35 of the UK GDPR.

The findings recorded in the enforcement notice are narrow and factual. Reddit "failed to apply any robust age assurance mechanism and therefore did not have a lawful basis for processing the personal information of children under the age of 13", and failed to carry out a data protection impact assessment addressing risks to children before January 2025. The ICO's accompanying release adds the timeline: provisional findings were issued to Reddit on 8 July 2025, Reddit introduced age assurance measures in July 2025 including age verification for mature content and self-declaration of age at sign-up, and the ICO told Reddit that reliance on self-declaration presents risks because it is easy to bypass. In setting the amount, the regulator states it took into account the number of children affected, the degree of potential harm, the duration of the failings, and Reddit's global turnover.

It was not an isolated action. The same release records that on 5 February 2026 the ICO fined MediaLab.AI, Inc., owner of the image hosting platform Imgur, £247,590 for failing to use children's personal information lawfully, and describes both as part of a programme following the ICO's December 2025 children's privacy progress update, focused on platforms that rely primarily on self-declaration. The ICO also notes it works with Ofcom, which enforces the Online Safety Act — two regulators, two statutes, one set of platforms.

The Children's code, formally the Age Appropriate Design Code, is the connective tissue here. It is a statutory code translating the legal requirements into design standards for online services likely to be accessed by under-18s, and section 81 of the 2025 Act has now put a related duty into Article 25(1B) itself.

What Is Still Moving

The Reddit penalty is not final. The ICO's release carries a dated update recording that on 1 April 2026 Reddit appealed its monetary penalty notice to the First-tier Tribunal. The monetary penalty notice itself was published on 19 March 2026. An appeal to the First-tier Tribunal is a rehearing rather than a review of the regulator's reasoning, so the findings above are the ICO's position rather than a settled legal conclusion.

The transfer instruments are also in motion. The ICO's guidance on standard data protection clauses carries a section headed "Will the IDTA and Addendum be updated to reflect the Data (Use and Access) Act coming into effect?" — an acknowledgement that the contractual templates were drafted against the pre-2025 text and that the "not materially lower" formulation now sits in the legislation above them.

The longer question is what accumulating divergence does to the December 2025 adequacy renewals. The Commission retains the power to monitor, and the 2025 Act removed the fixed four-year review period on the UK's own adequacy regulations without removing the monitoring obligation. Nothing in the material cited here states a view on how the next EU review will come out, and this guide does not offer one.

Background

For the underlying law rather than this development: Technology & SaaS privacy law.

Frequently Asked Questions

At what age can a child consent under the UK GDPR?
Article 8(1) of the UK GDPR as published on legislation.gov.uk provides that processing a child's personal data in relation to information society services is lawful where the child is at least 13. Below that age, processing is lawful only to the extent consent is given or authorised by the holder of parental responsibility. The number was written into Article 8(1) itself on 31 December 2020, when section 9 of the Data Protection Act 2018 was omitted.
Can EU standard contractual clauses be used for a transfer out of the UK?
Not on their own. The ICO states that the EU SCCs issued by the European Commission on 4 June 2021 "are not valid on their own for restricted transfers under the UK GDPR", but that its International Data Transfer Addendum lets an exporter rely on them. The alternative is the ICO's standalone International Data Transfer Agreement. Either route sits alongside a transfer risk assessment.
What changed about automated decisions under the Data (Use and Access) Act 2025?
Section 80 of the Act replaces Article 22 of the UK GDPR and section 14 of the DPA 2018 with new Articles 22A to 22D. DSIT describes the previous rules as framed as a general prohibition subject to limited conditions, and the new framework as more permissive, conditioned on safeguards: information about significant decisions, the ability to make representations and challenge them, and access to human intervention.
How large can an ICO fine be?
Section 157 of the Data Protection Act 2018 sets a higher maximum of £17,500,000 or 4% of an undertaking's total annual worldwide turnover in the preceding financial year, whichever is higher, and a standard maximum of £8,700,000 or 2% on the same formula. Where the person is not an undertaking, the figures are £17,500,000 and £8,700,000 flat.
Does a US company need a UK representative as well as an EU one?
Article 27 of the UK GDPR requires a controller or processor caught by Article 3(2) to designate in writing a representative in the United Kingdom, subject to the exemptions in Article 27(2). Article 27 of the EU GDPR imposes a parallel obligation for the Union. Whether either applies to a particular company depends on facts about its processing that an attorney would need to review.
Is the UK still adequate for transfers from the EU?
The European Commission's adequacy decisions page lists the United Kingdom under both the GDPR and the Law Enforcement Directive, as amended in December 2025 by one renewal decision under each. Technical extensions were published on 24 June 2025 and the renewal decisions on 19 December 2025. The UK is the only listed jurisdiction whose adequacy also covers law enforcement exchanges.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.